Advertisement
Guest User

Untitled

a guest
Sep 12th, 2024
83
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 16.13 KB | None | 0 0
  1. Log Name: System
  2. Source: LsaSrv
  3. Date: 13/09/2024 07:55:33
  4. Event ID: 6155
  5. Task Category: None
  6. Level: Warning
  7. Keywords:
  8. User: SYSTEM
  9. Computer: WIN-JS4IG1DT3CG
  10. Description:
  11. LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.
  12.  
  13. PackageName: tspkg
  14. Event Xml:
  15. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  16. <System>
  17. <Provider Name="LsaSrv" Guid="{199fe037-2b82-40a9-82ac-e1d46c792b99}" />
  18. <EventID>6155</EventID>
  19. <Version>0</Version>
  20. <Level>3</Level>
  21. <Task>0</Task>
  22. <Opcode>0</Opcode>
  23. <Keywords>0x8000000000000000</Keywords>
  24. <TimeCreated SystemTime="2024-09-13T05:55:33.0809929Z" />
  25. <EventRecordID>44</EventRecordID>
  26. <Correlation ActivityID="{89127efe-05a1-0004-8981-1289a105db01}" />
  27. <Execution ProcessID="872" ThreadID="876" />
  28. <Channel>System</Channel>
  29. <Computer>WIN-JS4IG1DT3CG</Computer>
  30. <Security UserID="S-1-5-18" />
  31. </System>
  32. <EventData>
  33. <Data Name="PackageName">tspkg</Data>
  34. </EventData>
  35. </Event>
  36.  
  37. Log Name: System
  38. Source: LsaSrv
  39. Date: 13/09/2024 07:55:33
  40. Event ID: 6155
  41. Task Category: None
  42. Level: Warning
  43. Keywords:
  44. User: SYSTEM
  45. Computer: WIN-JS4IG1DT3CG
  46. Description:
  47. LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.
  48.  
  49. PackageName: cloudap
  50. Event Xml:
  51. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  52. <System>
  53. <Provider Name="LsaSrv" Guid="{199fe037-2b82-40a9-82ac-e1d46c792b99}" />
  54. <EventID>6155</EventID>
  55. <Version>0</Version>
  56. <Level>3</Level>
  57. <Task>0</Task>
  58. <Opcode>0</Opcode>
  59. <Keywords>0x8000000000000000</Keywords>
  60. <TimeCreated SystemTime="2024-09-13T05:55:33.0879896Z" />
  61. <EventRecordID>46</EventRecordID>
  62. <Correlation ActivityID="{89127efe-05a1-0004-8981-1289a105db01}" />
  63. <Execution ProcessID="872" ThreadID="876" />
  64. <Channel>System</Channel>
  65. <Computer>WIN-JS4IG1DT3CG</Computer>
  66. <Security UserID="S-1-5-18" />
  67. </System>
  68. <EventData>
  69. <Data Name="PackageName">cloudap</Data>
  70. </EventData>
  71. </Event>
  72.  
  73. Log Name: System
  74. Source: LsaSrv
  75. Date: 13/09/2024 07:55:33
  76. Event ID: 6155
  77. Task Category: None
  78. Level: Warning
  79. Keywords:
  80. User: SYSTEM
  81. Computer: WIN-JS4IG1DT3CG
  82. Description:
  83. LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.
  84.  
  85. PackageName: pku2u
  86. Event Xml:
  87. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  88. <System>
  89. <Provider Name="LsaSrv" Guid="{199fe037-2b82-40a9-82ac-e1d46c792b99}" />
  90. <EventID>6155</EventID>
  91. <Version>0</Version>
  92. <Level>3</Level>
  93. <Task>0</Task>
  94. <Opcode>0</Opcode>
  95. <Keywords>0x8000000000000000</Keywords>
  96. <TimeCreated SystemTime="2024-09-13T05:55:33.0838251Z" />
  97. <EventRecordID>45</EventRecordID>
  98. <Correlation ActivityID="{89127efe-05a1-0004-8981-1289a105db01}" />
  99. <Execution ProcessID="872" ThreadID="876" />
  100. <Channel>System</Channel>
  101. <Computer>WIN-JS4IG1DT3CG</Computer>
  102. <Security UserID="S-1-5-18" />
  103. </System>
  104. <EventData>
  105. <Data Name="PackageName">pku2u</Data>
  106. </EventData>
  107. </Event>
  108.  
  109. Log Name: System
  110. Source: LsaSrv
  111. Date: 13/09/2024 07:55:33
  112. Event ID: 6155
  113. Task Category: None
  114. Level: Warning
  115. Keywords:
  116. User: SYSTEM
  117. Computer: WIN-JS4IG1DT3CG
  118. Description:
  119. LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.
  120.  
  121. PackageName: msv1_0
  122. Event Xml:
  123. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  124. <System>
  125. <Provider Name="LsaSrv" Guid="{199fe037-2b82-40a9-82ac-e1d46c792b99}" />
  126. <EventID>6155</EventID>
  127. <Version>0</Version>
  128. <Level>3</Level>
  129. <Task>0</Task>
  130. <Opcode>0</Opcode>
  131. <Keywords>0x8000000000000000</Keywords>
  132. <TimeCreated SystemTime="2024-09-13T05:55:33.0695731Z" />
  133. <EventRecordID>43</EventRecordID>
  134. <Correlation />
  135. <Execution ProcessID="872" ThreadID="876" />
  136. <Channel>System</Channel>
  137. <Computer>WIN-JS4IG1DT3CG</Computer>
  138. <Security UserID="S-1-5-18" />
  139. </System>
  140. <EventData>
  141. <Data Name="PackageName">msv1_0</Data>
  142. </EventData>
  143. </Event>
  144.  
  145. Log Name: System
  146. Source: LsaSrv
  147. Date: 13/09/2024 07:55:33
  148. Event ID: 6155
  149. Task Category: None
  150. Level: Warning
  151. Keywords:
  152. User: SYSTEM
  153. Computer: WIN-JS4IG1DT3CG
  154. Description:
  155. LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.
  156.  
  157. PackageName: negoexts
  158. Event Xml:
  159. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  160. <System>
  161. <Provider Name="LsaSrv" Guid="{199fe037-2b82-40a9-82ac-e1d46c792b99}" />
  162. <EventID>6155</EventID>
  163. <Version>0</Version>
  164. <Level>3</Level>
  165. <Task>0</Task>
  166. <Opcode>0</Opcode>
  167. <Keywords>0x8000000000000000</Keywords>
  168. <TimeCreated SystemTime="2024-09-13T05:55:33.0422292Z" />
  169. <EventRecordID>41</EventRecordID>
  170. <Correlation />
  171. <Execution ProcessID="872" ThreadID="876" />
  172. <Channel>System</Channel>
  173. <Computer>WIN-JS4IG1DT3CG</Computer>
  174. <Security UserID="S-1-5-18" />
  175. </System>
  176. <EventData>
  177. <Data Name="PackageName">negoexts</Data>
  178. </EventData>
  179. </Event>
  180.  
  181. Log Name: System
  182. Source: Microsoft-Windows-Wininit
  183. Date: 13/09/2024 07:55:32
  184. Event ID: 15
  185. Task Category: None
  186. Level: Warning
  187. Keywords:
  188. User: SYSTEM
  189. Computer: WIN-JS4IG1DT3CG
  190. Description:
  191. Credential Guard and/or VBS Key Isolation are configured but the secure kernel is not running; continuing without them.
  192. Event Xml:
  193. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  194. <System>
  195. <Provider Name="Microsoft-Windows-Wininit" Guid="{206f6dea-d3c5-4d10-bc72-989f03c8b84b}" />
  196. <EventID>15</EventID>
  197. <Version>0</Version>
  198. <Level>3</Level>
  199. <Task>0</Task>
  200. <Opcode>0</Opcode>
  201. <Keywords>0x4000000000000000</Keywords>
  202. <TimeCreated SystemTime="2024-09-13T05:55:32.9713642Z" />
  203. <EventRecordID>38</EventRecordID>
  204. <Correlation />
  205. <Execution ProcessID="704" ThreadID="708" />
  206. <Channel>System</Channel>
  207. <Computer>WIN-JS4IG1DT3CG</Computer>
  208. <Security UserID="S-1-5-18" />
  209. </System>
  210. <EventData>
  211. </EventData>
  212. </Event>
  213.  
  214. Log Name: System
  215. Source: LsaSrv
  216. Date: 13/09/2024 07:55:33
  217. Event ID: 6155
  218. Task Category: None
  219. Level: Warning
  220. Keywords:
  221. User: SYSTEM
  222. Computer: WIN-JS4IG1DT3CG
  223. Description:
  224. LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.
  225.  
  226. PackageName: kerberos
  227. Event Xml:
  228. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  229. <System>
  230. <Provider Name="LsaSrv" Guid="{199fe037-2b82-40a9-82ac-e1d46c792b99}" />
  231. <EventID>6155</EventID>
  232. <Version>0</Version>
  233. <Level>3</Level>
  234. <Task>0</Task>
  235. <Opcode>0</Opcode>
  236. <Keywords>0x8000000000000000</Keywords>
  237. <TimeCreated SystemTime="2024-09-13T05:55:33.0512834Z" />
  238. <EventRecordID>42</EventRecordID>
  239. <Correlation />
  240. <Execution ProcessID="872" ThreadID="876" />
  241. <Channel>System</Channel>
  242. <Computer>WIN-JS4IG1DT3CG</Computer>
  243. <Security UserID="S-1-5-18" />
  244. </System>
  245. <EventData>
  246. <Data Name="PackageName">kerberos</Data>
  247. </EventData>
  248. </Event>
  249.  
  250. Log Name: System
  251. Source: Service Control Manager
  252. Date: 13/09/2024 07:55:39
  253. Event ID: 7023
  254. Task Category: None
  255. Level: Error
  256. Keywords: Classic
  257. User: N/A
  258. Computer: WIN-JS4IG1DT3CG
  259. Description:
  260. The netprofm service terminated with the following error:
  261. The device is not ready.
  262. Event Xml:
  263. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  264. <System>
  265. <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
  266. <EventID Qualifiers="49152">7023</EventID>
  267. <Version>0</Version>
  268. <Level>2</Level>
  269. <Task>0</Task>
  270. <Opcode>0</Opcode>
  271. <Keywords>0x8080000000000000</Keywords>
  272. <TimeCreated SystemTime="2024-09-13T05:55:39.9085701Z" />
  273. <EventRecordID>63</EventRecordID>
  274. <Correlation />
  275. <Execution ProcessID="848" ThreadID="940" />
  276. <Channel>System</Channel>
  277. <Computer>WIN-JS4IG1DT3CG</Computer>
  278. <Security />
  279. </System>
  280. <EventData>
  281. <Data Name="param1">netprofm</Data>
  282. <Data Name="param2">%%21</Data>
  283. <Binary>6E0065007400700072006F0066006D000000</Binary>
  284. </EventData>
  285. </Event>
  286.  
  287. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  288. Source: Microsoft-Windows-AppModel-Runtime
  289. Date: 13/09/2024 07:55:33
  290. Event ID: 21
  291. Task Category: None
  292. Level: Error
  293. Keywords: (70368744177664),AppContainer
  294. User: SYSTEM
  295. Computer: WIN-JS4IG1DT3CG
  296. Description:
  297. CreateAppContainerProfile failed for AppContainer onecore\ds\security\gina\profile\profext\appcontainer.cpp Line:1886 Usermode Font Driver Host microsoft.windows.fontdrvhost with error 0x8007000A.
  298. Event Xml:
  299. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  300. <System>
  301. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{f1ef270a-0d32-4352-ba52-dbab41e1d859}" />
  302. <EventID>21</EventID>
  303. <Version>0</Version>
  304. <Level>2</Level>
  305. <Task>0</Task>
  306. <Opcode>0</Opcode>
  307. <Keywords>0x2000400000000002</Keywords>
  308. <TimeCreated SystemTime="2024-09-13T05:55:33.2497648Z" />
  309. <EventRecordID>1</EventRecordID>
  310. <Correlation />
  311. <Execution ProcessID="704" ThreadID="780" />
  312. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  313. <Computer>WIN-JS4IG1DT3CG</Computer>
  314. <Security UserID="S-1-5-18" />
  315. </System>
  316. <EventData>
  317. <Data Name="ErrorCode">2147942410</Data>
  318. <Data Name="Context">onecore\ds\security\gina\profile\profext\appcontainer.cpp Line:1886 Usermode Font Driver Host microsoft.windows.fontdrvhost</Data>
  319. </EventData>
  320. </Event>
  321.  
  322. Log Name: Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin
  323. Source: Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider
  324. Date: 13/09/2024 07:57:13
  325. Event ID: 844
  326. Task Category: None
  327. Level: Error
  328. Keywords:
  329. User: SYSTEM
  330. Computer: WIN-JS4IG1DT3CG
  331. Description:
  332. MDM PolicyManager: During Inbox found bad enrollment (82965F5A-6C65-4B7A-8075-488FCCE07D4E) during merge. Requesting merge (1e05dd5d-a022-46c5-963c-b20de341170f). Deleting policies for the enrollment. Enrollment state is (Your file waiting to be printed was deleted.).
  333. Event Xml:
  334. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  335. <System>
  336. <Provider Name="Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider" Guid="{3da494e4-0fe2-415c-b895-fb5265c5c83b}" />
  337. <EventID>844</EventID>
  338. <Version>0</Version>
  339. <Level>2</Level>
  340. <Task>0</Task>
  341. <Opcode>0</Opcode>
  342. <Keywords>0x8000000000000000</Keywords>
  343. <TimeCreated SystemTime="2024-09-13T05:57:13.6472404Z" />
  344. <EventRecordID>2</EventRecordID>
  345. <Correlation />
  346. <Execution ProcessID="1116" ThreadID="1144" />
  347. <Channel>Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin</Channel>
  348. <Computer>WIN-JS4IG1DT3CG</Computer>
  349. <Security UserID="S-1-5-18" />
  350. </System>
  351. <EventData>
  352. <Data Name="Message1">Inbox</Data>
  353. <Data Name="Message2">82965F5A-6C65-4B7A-8075-488FCCE07D4E</Data>
  354. <Data Name="Message3">1e05dd5d-a022-46c5-963c-b20de341170f</Data>
  355. <Data Name="HRESULT">0x3f</Data>
  356. </EventData>
  357. </Event>
  358.  
  359. Log Name: System
  360. Source: LsaSrv
  361. Date: 13/09/2024 07:55:33
  362. Event ID: 6155
  363. Task Category: None
  364. Level: Warning
  365. Keywords:
  366. User: SYSTEM
  367. Computer: WIN-JS4IG1DT3CG
  368. Description:
  369. LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.
  370.  
  371. PackageName: msv1_0
  372. Event Xml:
  373. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  374. <System>
  375. <Provider Name="LsaSrv" Guid="{199fe037-2b82-40a9-82ac-e1d46c792b99}" />
  376. <EventID>6155</EventID>
  377. <Version>0</Version>
  378. <Level>3</Level>
  379. <Task>0</Task>
  380. <Opcode>0</Opcode>
  381. <Keywords>0x8000000000000000</Keywords>
  382. <TimeCreated SystemTime="2024-09-13T05:55:33.1219892Z" />
  383. <EventRecordID>50</EventRecordID>
  384. <Correlation ActivityID="{89127efe-05a1-0004-8981-1289a105db01}" />
  385. <Execution ProcessID="872" ThreadID="876" />
  386. <Channel>System</Channel>
  387. <Computer>WIN-JS4IG1DT3CG</Computer>
  388. <Security UserID="S-1-5-18" />
  389. </System>
  390. <EventData>
  391. <Data Name="PackageName">msv1_0</Data>
  392. </EventData>
  393. </Event>
  394.  
  395. Log Name: System
  396. Source: LsaSrv
  397. Date: 13/09/2024 07:55:33
  398. Event ID: 6155
  399. Task Category: None
  400. Level: Warning
  401. Keywords:
  402. User: SYSTEM
  403. Computer: WIN-JS4IG1DT3CG
  404. Description:
  405. LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.
  406.  
  407. PackageName: wdigest
  408. Event Xml:
  409. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  410. <System>
  411. <Provider Name="LsaSrv" Guid="{199fe037-2b82-40a9-82ac-e1d46c792b99}" />
  412. <EventID>6155</EventID>
  413. <Version>0</Version>
  414. <Level>3</Level>
  415. <Task>0</Task>
  416. <Opcode>0</Opcode>
  417. <Keywords>0x8000000000000000</Keywords>
  418. <TimeCreated SystemTime="2024-09-13T05:55:33.1123166Z" />
  419. <EventRecordID>47</EventRecordID>
  420. <Correlation ActivityID="{89127efe-05a1-0004-8981-1289a105db01}" />
  421. <Execution ProcessID="872" ThreadID="876" />
  422. <Channel>System</Channel>
  423. <Computer>WIN-JS4IG1DT3CG</Computer>
  424. <Security UserID="S-1-5-18" />
  425. </System>
  426. <EventData>
  427. <Data Name="PackageName">wdigest</Data>
  428. </EventData>
  429. </Event>
  430.  
  431. Log Name: System
  432. Source: LsaSrv
  433. Date: 13/09/2024 07:55:33
  434. Event ID: 6155
  435. Task Category: None
  436. Level: Warning
  437. Keywords:
  438. User: SYSTEM
  439. Computer: WIN-JS4IG1DT3CG
  440. Description:
  441. LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.
  442.  
  443. PackageName: schannel
  444. Event Xml:
  445. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  446. <System>
  447. <Provider Name="LsaSrv" Guid="{199fe037-2b82-40a9-82ac-e1d46c792b99}" />
  448. <EventID>6155</EventID>
  449. <Version>0</Version>
  450. <Level>3</Level>
  451. <Task>0</Task>
  452. <Opcode>0</Opcode>
  453. <Keywords>0x8000000000000000</Keywords>
  454. <TimeCreated SystemTime="2024-09-13T05:55:33.1172779Z" />
  455. <EventRecordID>48</EventRecordID>
  456. <Correlation ActivityID="{89127efe-05a1-0004-8981-1289a105db01}" />
  457. <Execution ProcessID="872" ThreadID="876" />
  458. <Channel>System</Channel>
  459. <Computer>WIN-JS4IG1DT3CG</Computer>
  460. <Security UserID="S-1-5-18" />
  461. </System>
  462. <EventData>
  463. <Data Name="PackageName">schannel</Data>
  464. </EventData>
  465. </Event>
  466.  
  467. Log Name: System
  468. Source: LsaSrv
  469. Date: 13/09/2024 07:55:33
  470. Event ID: 6155
  471. Task Category: None
  472. Level: Warning
  473. Keywords:
  474. User: SYSTEM
  475. Computer: WIN-JS4IG1DT3CG
  476. Description:
  477. LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.
  478.  
  479. PackageName: sfapm
  480. Event Xml:
  481. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  482. <System>
  483. <Provider Name="LsaSrv" Guid="{199fe037-2b82-40a9-82ac-e1d46c792b99}" />
  484. <EventID>6155</EventID>
  485. <Version>0</Version>
  486. <Level>3</Level>
  487. <Task>0</Task>
  488. <Opcode>0</Opcode>
  489. <Keywords>0x8000000000000000</Keywords>
  490. <TimeCreated SystemTime="2024-09-13T05:55:33.1216503Z" />
  491. <EventRecordID>49</EventRecordID>
  492. <Correlation ActivityID="{89127efe-05a1-0004-8981-1289a105db01}" />
  493. <Execution ProcessID="872" ThreadID="876" />
  494. <Channel>System</Channel>
  495. <Computer>WIN-JS4IG1DT3CG</Computer>
  496. <Security UserID="S-1-5-18" />
  497. </System>
  498. <EventData>
  499. <Data Name="PackageName">sfapm</Data>
  500. </EventData>
  501. </Event>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement